CVE-2007-1263

high

Description

GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and unsigned portions of OpenPGP messages with multiple components, which might allow remote attackers to forge the contents of a message without detection.

References

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10496

https://issues.rpath.com/browse/RPL-1111

http://www.vupen.com/english/advisories/2007/0835

http://www.ubuntu.com/usn/usn-432-2

http://www.ubuntu.com/usn/usn-432-1

http://www.trustix.org/errata/2007/0009/

http://www.securitytracker.com/id?1017727

http://www.securityfocus.com/bid/22757

http://www.securityfocus.com/archive/1/461958/30/7710/threaded

http://www.securityfocus.com/archive/1/461958/100/0/threaded

http://www.redhat.com/support/errata/RHSA-2007-0107.html

http://www.redhat.com/support/errata/RHSA-2007-0106.html

http://www.mandriva.com/security/advisories?name=MDKSA-2007:059

http://www.debian.org/security/2007/dsa-1266

http://www.coresecurity.com/?action=item&id=1687

http://support.avaya.com/elmodocs2/security/ASA-2007-144.htm

http://securityreason.com/securityalert/2353

http://secunia.com/advisories/24875

http://secunia.com/advisories/24734

http://secunia.com/advisories/24650

http://secunia.com/advisories/24544

http://secunia.com/advisories/24511

http://secunia.com/advisories/24489

http://secunia.com/advisories/24438

http://secunia.com/advisories/24420

http://secunia.com/advisories/24419

http://secunia.com/advisories/24407

http://secunia.com/advisories/24365

http://lists.suse.com/archive/suse-security-announce/2007-Mar/0008.html

http://lists.gnupg.org/pipermail/gnupg-users/2007-March/030514.html

http://fedoranews.org/cms/node/2776

http://fedoranews.org/cms/node/2775

Details

Source: Mitre, NVD

Published: 2007-03-06

Updated: 2018-10-16

Risk Information

CVSS v2

Base Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 7.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Severity: High